AI in Hiring: What Small Businesses Need to Know About the New Compliance Rules
By Alex Santos, M.S., M.B.A. • Founder, Nimble Advisors.
Last updated: July 2026
If your business uses any tool that screens, scores, ranks, or filters job applicants, you may already be subject to laws you've never heard of. As of mid-2026, a patchwork of state and local rules governs the use of artificial intelligence in employment decisions — with distinct obligations in Colorado, Illinois, California, Texas, and New York City, and more states following. Requirements vary but commonly include notifying candidates when AI influences a decision, conducting bias audits, performing impact assessments, and offering alternative selection processes. Critically, these laws generally apply based on where the applicant or employee is located, not where your company is headquartered — and having a human make the final call does not necessarily exempt you. Existing anti-discrimination law applies regardless: under Title VII, the employer is liable when an AI tool produces discriminatory outcomes, even if a vendor built it.
Most small and mid-sized businesses reading that paragraph will have the same reaction: we don't use AI in hiring.
You probably do. That's the problem.
If your applicant tracking system ranks candidates, if you use LinkedIn Recruiter's recommendations, if Indeed's tools screen applicants before you see them, if you use a resume parser that filters on keywords, or if any vendor in your hiring stack "scores" candidates — you may be deploying what these laws call an automated employment decision tool. Most SMB owners have no idea, because nobody sold it to them that way. It was just a feature.
This guide explains what the rules actually require, which states have them, how to tell whether you're covered, and what to do about it. For the broader compliance picture, see our HR Compliance guide for small and mid-sized businesses. Because these obligations follow your applicants across state lines, the companion piece is Multi-State HR Compliance.
This is an educational resource, not legal advice. This area is changing quickly. For specific situations, consult employment counsel or a fractional HR partner.
The Trap: You're Probably Already Using AI in Hiring
The laws in this area don't regulate "AI" in the science-fiction sense. They regulate automated decision systems — software that substantially assists or replaces human judgment in an employment decision.
That definition sweeps in a lot of ordinary tools:
Applicant tracking systems that rank, score, or auto-reject candidates
Resume screening and parsing tools that filter on keywords or knock out applicants who don't match criteria
Job board features that surface "best match" candidates or screen out others before you see them
Video interview platforms that score responses, tone, or facial expression
Assessment and personality tools that generate a pass/fail or a numeric fit score
Chatbot screeners that qualify or disqualify applicants
Background check tools that make automated adverse-action determinations
If you've never asked your ATS vendor whether their product ranks candidates, that's the first phone call to make after reading this.
The most dangerous assumption: "We have a human review every decision, so we're fine." New York City's guidance directly addresses this — the law applies even when humans make the final decisions based on AI rankings or scores. If the tool is influencing the decision, the obligation generally attaches. A human rubber-stamping an algorithm's shortlist is not a defense.
The State Patchwork (Mid-2026)
There is no federal AI employment law. States have filled the gap, and they have not coordinated. Here's the current landscape.
Colorado — the Colorado AI Act (SB 24-205)
Effective June 30, 2026. The most comprehensive state AI law to date, and the newest.
It creates a dual-obligation structure. Companies that build AI systems are "developers." Companies that use AI in employment decisions are "deployers" — which is you. Any AI system affecting hiring, termination, promotion, or similar decisions is treated as a "high-risk system."
Core obligations for deployers include:
Risk assessments — evaluate high-risk AI systems to identify and mitigate potential harm
Transparency notices — inform candidates and employees when AI influences employment decisions like hiring, firing, or promotion
Ongoing risk management — treat AI oversight as a continuing compliance function, not a one-time review
The reach is the part SMBs miss: the Act applies to entities doing business in Colorado regardless of where the entity is located. A Miami company with one remote employee or one Colorado applicant can be covered.
Illinois — HB 3773
Effective January 1, 2026. Amends the Illinois Human Rights Act to expressly prohibit employers from using AI in ways that result in discrimination against protected classes — whether or not the discrimination was intentional. Employers must also notify employees and candidates when AI is used in employment decisions.
The "intent doesn't matter" standard is the significant part. You can be liable for a disparate outcome you never intended and didn't know about.
California — automated-decision system regulations
Effective October 1, 2025. California's rules are among the most detailed. They make it unlawful to use any automated-decision system that discriminates against applicants or employees based on protected traits in decisions about recruitment, hiring, promotion, training, pay, benefits, leave, or termination.
Note the scope: this reaches well beyond hiring into the full employment lifecycle.
New York City — Local Law 144
Effective July 5, 2023 — the earliest of these, and still the strictest on process. Employers using automated employment decision tools (AEDTs) for hiring or promotion must:
Conduct an annual bias audit performed by an independent auditor
Publicly post the audit summary and the tool's deployment date on the careers page
Notify candidates and employees at least 10 business days before using an AEDT
Offer an alternative selection process on request
Noncompliance carries fines of $500 to $1,000 per violation — and violations can be counted per candidate, which adds up quickly at volume.
Texas — TRAIGA
Effective January 1, 2026. Deliberately business-friendly and a useful contrast. It prohibits only intentional AI-based discrimination, does not require audits, impact assessments, or user disclosures, and grants employers a 60-day notice-and-cure period before enforcement.
Texas is the model other business-friendly states are likely to follow — which means the patchwork is going to get more varied, not less.
Also active
New Jersey has adopted AI regulation, and additional states have measures enacted or pending. This list will be longer within a year.
Florida
Florida has not enacted an AI employment law. Consistent with its generally light regulatory posture (see our Florida HR Compliance Guide), Florida employers face no state-specific AI hiring mandate today.
That is not the same as having no exposure. If you post a remote role that a Colorado or Illinois resident can apply for, or you employ someone in California, those states' rules can reach you. Florida's silence protects you only for your Florida-only hiring.
Federal Law Applies Regardless
This is the point most coverage buries, and it matters more than any state statute.
Title VII, the ADA, and the ADEA already prohibit discriminatory employment outcomes. The EEOC has made clear that employers remain fully responsible under Title VII when AI-driven tools produce discriminatory results. If an algorithm produces a disparate impact on a protected class, liability attaches regardless of whether you built the tool or bought it from a vendor.
"The software did it" is not a defense. Neither is "the vendor said it was validated."
Two further federal exposures:
Disability discrimination. A video-interview tool that scores speech patterns or facial expression may screen out candidates with disabilities. A timed assessment may disadvantage candidates entitled to accommodation. The ADA obligation to provide reasonable accommodation applies to your selection process, including the automated parts.
FCRA. Where AI is used in background checks, inaccurate or fabricated information and automated adverse-action determinations can implicate the Fair Credit Reporting Act. Human review remains critical.
There is also active litigation shaping this space — most prominently Mobley v. Workday, in which plaintiffs allege a vendor's screening products produced discriminatory outcomes across many employers. Cases like it raise the prospect of liability extending in directions the market hasn't priced in yet.
What This Actually Means for a 40-Person Company
Let's be practical. You are not going to hire a Chief AI Ethics Officer.
Here's the realistic risk picture for a small or mid-sized employer:
Your genuine exposure is disparate impact, not a state filing violation. The likeliest way this hurts you is not a Colorado regulator knocking on your door. It's a rejected applicant, or a plaintiff's attorney, discovering that your screening tool systematically filtered out candidates over 50, or candidates with employment gaps that correlate with caregiving, or candidates from certain ZIP codes.
Your second exposure is a notice failure. Several of these laws require you to tell candidates AI is involved. That's a cheap thing to comply with and an easy thing to get caught not doing, because the evidence is simply the absence of the disclosure on your careers page.
Your third exposure is your vendor. You are liable for what their tool does. Most SMB contracts with ATS and screening vendors contain no meaningful indemnity for algorithmic discrimination, and many vendors have not conducted the bias audits these laws contemplate.
A Practical Compliance Checklist
Six steps, in order of value:
1. Inventory your hiring stack. List every tool that touches an applicant between "applies" and "human reads the resume." Include your ATS, job boards, assessments, scheduling tools, and background check provider. Most companies find more than they expected.
2. Ask each vendor three questions in writing.
Does your product rank, score, filter, or auto-reject applicants?
Have you conducted a bias audit, and can we see the results?
What are our disclosure obligations when using your tool?
Get the answers in writing. If a vendor won't answer, that itself is information.
3. Map your applicant geography, not just your employee geography. These laws generally follow the applicant. If you post remote roles, you're potentially subject to the rules of every state your applicants sit in. This is the same analysis as multi-state employment compliance, applied to your funnel instead of your payroll.
4. Add a disclosure to your job postings and careers page. Plain language, stating that automated tools may be used in the review of applications and that candidates may request an alternative process. This is cheap insurance and it satisfies a common requirement across several jurisdictions.
5. Keep a human genuinely in the loop — and document it. Not as a rubber stamp on an algorithmic shortlist, but as a real reviewer with the authority and the information to override. Document the review.
6. Audit your outcomes, not just your process. Periodically look at who your funnel is actually selecting and rejecting, broken down by protected characteristics where you can lawfully do so. Disparate impact is measured in outcomes. If your process is producing a skewed result, the fact that you followed a procedure will not save you.
What to Do If You've Been Using AI Tools Without Any of This
Don't panic, and don't rip the tools out.
Do this instead:
Document the current state. What tools, since when, in which states.
Get the vendor bias audit if one exists. If it doesn't, that's a material finding.
Add the disclosure immediately. It's the fastest exposure to close.
Review your rejection data for obvious skews.
Talk to employment counsel before you make any written admission about past practice — including in an internal email.
The distinction that matters is between fixing forward and creating a record of known violation. Get advice before you write anything down.
When to Bring in Help
You use an ATS or screening tool and can't answer whether it ranks candidates
You hire remotely and don't know which states your applicants come from
You have applicants or employees in Colorado, Illinois, California, or New York City
You're scaling hiring and adding automation to keep up
You've had a rejected applicant raise a question about your process
Your vendor can't produce a bias audit
This is a genuinely new area where the cost of a wrong guess is high and the cost of getting it right is low. It's also exactly the kind of problem that doesn't announce itself until it's a claim.
Nimble Advisors provides fractional HR for companies with 10–250 employees. We'll inventory your hiring stack, map your obligations against where your applicants actually are, and get your disclosures in place.
This article is provided for general educational purposes and does not constitute legal advice. AI employment law is developing rapidly, and requirements vary significantly by jurisdiction and by employer size. Consult employment counsel or a qualified HR professional for guidance specific to your situation.
Last reviewed: July 2026. Next scheduled review: October 2026.
Frequently Asked Questions
-
Possibly, and it depends less on your size than on where your applicants and employees are located. Several state and local AI employment laws apply based on the location of the applicant or employee rather than the employer's headquarters. Colorado's AI Act, for example, applies to entities doing business in Colorado regardless of where the entity is located. If you post remote roles or employ people across state lines, you may be covered by rules in states you have no office in. Some laws also carry employer-size or tool-specific thresholds, so the specific analysis depends on your facts.
-
Broader than most employers assume. These laws generally regulate automated decision systems that substantially assist or replace human judgment — which can include applicant tracking systems that rank or score candidates, resume screening and parsing tools, job board matching features, video interview platforms that score responses, automated assessments, chatbot screeners, and background check tools that make automated adverse-action determinations. Many employers are using covered tools without realizing it, because the capability was bundled as a product feature rather than sold as "AI."
-
Not necessarily. New York City's guidance on Local Law 144 confirms the law applies even when humans make final decisions based on AI-generated rankings or scores. If an automated tool is influencing the decision — narrowing the pool, ordering candidates, flagging applicants — the obligation can attach. A human approving an algorithm's shortlist is generally not sufficient.
-
The Colorado Artificial Intelligence Act (SB 24-205) took effect June 30, 2026. It classifies employers who use AI in employment decisions as "deployers" of "high-risk systems" and imposes obligations including risk assessments and transparency notices to candidates and employees when AI influences decisions like hiring, firing, or promotion. It applies to entities doing business in Colorado regardless of the entity's own location, which means out-of-state employers with Colorado applicants or employees can be covered.
-
Employers using automated employment decision tools for hiring or promotion in New York City must conduct an annual bias audit by an independent auditor, publicly post the audit summary and the tool's deployment date, notify candidates and employees at least 10 business days before using the tool, and offer an alternative selection process on request. Penalties range from $500 to $1,000 per violation.
-
Generally yes. The EEOC has made clear that employers remain responsible under Title VII when AI-driven tools produce discriminatory outcomes, and liability attaches regardless of whether the tool was built internally or procured from a third party. Vendor assurances do not transfer legal responsibility. Most small-business vendor contracts contain no meaningful indemnity for algorithmic discrimination, so review your agreements and ask vendors directly for their bias audit results.
-
No. Florida has not enacted a state law regulating AI in employment decisions, consistent with its generally light-touch regulatory approach. However, Florida employers are still subject to federal anti-discrimination law, which applies to AI-driven outcomes, and to the laws of other states where their applicants or employees are located. A Florida company hiring remotely can be covered by Colorado, Illinois, or California rules.
-
Three steps, in order. First, inventory every tool that touches an applicant before a human reads their resume — most employers find more than they expected. Second, add a plain-language disclosure to your job postings and careers page stating that automated tools may be used and that candidates can request an alternative process; this is inexpensive and satisfies a common requirement across jurisdictions. Third, review your actual hiring outcomes for disparate impact, since liability under federal law turns on results rather than intentions.